Suspect
PE Executable
MD5: c99a6f0ab9d6577cfb961b911bead78f
Size: 734.72 KB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Low
| MD5 | c99a6f0ab9d6577cfb961b911bead78f |
| Sha1 | 7e2a19a78582bbd5043adbf08a74951bc78b62e0 |
| Sha256 | a6d4a7d43d4868e871e0caac0ac2cbaa742a1c0a2416ce70c43a5e1c418d4a64 |
| Sha384 | df9ee875d051127d4684623b876a1ebcc07868185d1265bb78e6281bae298b708750e83aa643d31c5b2aa1639eebd410 |
| Sha512 | 0fce3c3cd499b98a8fa278219bc7bf2d6e911de865c755e4e29b34d39e008edd5d6e155fa3d17cfc396dc48bf66503e2ef8c43b85ae0b528040f605b791de843 |
| SSDeep | 12288:+GbXRFbxQ4sVlmZfR3hI5TzK0EnXOt2cka6A0aKyRROpDbN:+MRFNh2kfRRqwXOt2cka6ph7pD |
| TLSH | 7AF42315A6A49327C1AD47F553E3127013F13C493222C61D998DB8FFACB2B48A6E47E7 |
PeID
Microsoft Visual C++ v6.0 DLL
STICH
beta
No STICH Path has been generated for this analysis yet.
3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.
bin
2img
1| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | PDB Path: NJpo.pdb |
| Module Name | NJpo.exe |
| Full Name | NJpo.exe |
| EntryPoint | System.Void DesktopApp.AlwaysOnTop.App::Main() |
| Scope Name | NJpo.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | NJpo |
| Assembly Version | 0.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.0 |
| Total Strings | 100 |
| Main Method | System.Void DesktopApp.AlwaysOnTop.App::Main() |
| Main IL Instruction Count | 10 |
| Main IL | |